Live data from Hacker News

Fraud possible in Brazil's e-voting system

zdnet.com

41–50 of 54 posts

Re: Fraud possible in Brazil's e-voting system

#41
post #36

Earlier quoted context omitted.

How does pret a voter protect voter privacy in a voter pool (precinct) of 400 with a ballot containing 30 issues. Go ahead, work it out for yourself, manually, like I did. I'll wait.

The premise of whatever it was that you were manually working out was that "all crypto based systems rely on hash collisions to protect voter privacy". Again, pray tell, how does Pret a Voter rely on hash collisions?

Down vote? Petty.

You're right, of course. I conflated Pret a Voter with another hare brained scheme: Chaum's Punchscan, which at least makes a token attempt to protect voter privacy. My apologies. (It's been a few years since I studied this nonsense.)

Pret a voter does not throw information away (a la secure one-way hash), it merely obfuscates the process. It's just a more fancy kabuki.

Re: Fraud possible in Brazil's e-voting system

#42

Earlier quoted context omitted.

Your enthusiasm for vote by mail is unwarranted. Who will deliver the ballots once the USPS goes away? The push for e-voting will really heat up then. I encourage you learn how your local jurisdiction handles mail ballots. It's more or less making sausage. The UAA is 1% (both directions). A large percent are challenged during signature verification. Ballots are electronically scanned (like a fax or OCR) as they arriv…

> The only meaningful future electronic mediated system must be completely transparent ... Sacrificing voter privacy to ensure election integrity. It's possible to get a quite good amount of privacy by the use of pseudonyms. You won't get a system with verifiable guarantees of both confidentiality and accuracy, as that's impossible, but there's no reason we can not make it as good as paper ballots.

How would pseudonyms work? How do I know that Skippy or voter # 123 is eligible to vote in my precinct?

Re: Fraud possible in Brazil's e-voting system

#43

Earlier quoted context omitted.

> The only meaningful future electronic mediated system must be completely transparent ... Sacrificing voter privacy to ensure election integrity. It's possible to get a quite good amount of privacy by the use of pseudonyms. You won't get a system with verifiable guarantees of both confidentiality and accuracy, as that's impossible, but there's no reason we can not make it as good as paper ballots.

How would pseudonyms work? How do I know that Skippy or voter # 123 is eligible to vote in my precinct?

You can control who got a valid pseudonyms, and how many they are. And you can distribute pseudonym validation and make it visible enough that you make sure people don't record them.

Re: Fraud possible in Brazil's e-voting system

#44

Earlier quoted context omitted.

How would pseudonyms work? How do I know that Skippy or voter # 123 is eligible to vote in my precinct?

You can control who got a valid pseudonyms, and how many they are. And you can distribute pseudonym validation and make it visible enough that you make sure people don't record them.

[deleted]

Re: Fraud possible in Brazil's e-voting system

#45

Earlier quoted context omitted.

How would pseudonyms work? How do I know that Skippy or voter # 123 is eligible to vote in my precinct?

You can control who got a valid pseudonyms, and how many they are. And you can distribute pseudonym validation and make it visible enough that you make sure people don't record them.

[deleted]

Re: Fraud possible in Brazil's e-voting system

#46

Earlier quoted context omitted.

How would pseudonyms work? How do I know that Skippy or voter # 123 is eligible to vote in my precinct?

You can control who got a valid pseudonyms, and how many they are. And you can distribute pseudonym validation and make it visible enough that you make sure people don't record them.

I don't know enough about your proposal to comment meaningfully.

I can speak to my experience as an election integrity activist.

A very large fraction of people who care about our elections (in the USA) would respond poorly to your proposal of not using real names when voting. You may be aware of the recurring "voter fraud" kerfuffle that gets trotted out every cycle. Scandal worthy shenanigans such as dogs registered to vote and renown critic Ann Coulter falsifying her voter registration.

The only current partial exception to using real names that I'm aware of protecting the identity of vulnerable persons, such as witness protection, victim of domestic violence, and maybe public figures like judges. The idea being to enfranchise those who would be endangered if their identity and location were freely available. So there's separate handling of these person's voter registration and ballot processing. More I can't say, because that's not an aspect that I studied in depth.

Also...

I learned the hard way that any critic of the current system (e.g. proposing alternatives) will be dismissed out of hand by administrators and policymakers if they don't have complete mastery of the current system. Conspiracy theorist, gadfly, crank, kook, paranoid, etc. And you will be tested.

If you develop your idea further, please cc me. Protecting voter privacy is very important to me, and I'd welcome a solution.

Re: Fraud possible in Brazil's e-voting system

#47

I doubt Brazil is ever going back to paper voting. With that said, human vote counting is exploitable/error-prone, too, and electronic vote counting instead of electronic voting seems like it'd have the same issues the voting machine has. The solution is clear to me, make it open-source, give bounties for issue-fixing. If the current software is crap hire RSA and/or some nice software shop to refactor and audit it, t…

All systems are fallible. Assess the relative risks by comparing their attack surface areas.

Paper ballots issued, cast, and counted per precinct, the night of the election is the most robust system existent. Compared to any other system, corruption would require more participants, increasing the cost, difficulty, and risk of detection.

Further, it also enables verifying the physical chain of custody, which is very, very difficult with electronic systems.

RSA? Why would I trust them?

Re: Fraud possible in Brazil's e-voting system

#48

Earlier quoted context omitted.

You can control who got a valid pseudonyms, and how many they are. And you can distribute pseudonym validation and make it visible enough that you make sure people don't record them.

I don't know enough about your proposal to comment meaningfully. I can speak to my experience as an election integrity activist. A very large fraction of people who care about our elections (in the USA) would respond poorly to your proposal of not using real names when voting. You may be aware of the recurring "voter fraud" kerfuffle that gets trotted out every cycle. Scandal worthy shenanigans such as dogs registere…

I don't have a finished solution. I only think about it sometimes, but got a promising set of ideas.

A possible protocol for using pseudonyms could be that people create a random IDs at home, and get them signed under a public setup very like our current setup for voting - several people sign it, and each person signs a limited number of IDs. Those people then give the signatures to the voter, and mark in a control that he got the ID. An ID is valid if it has all the signatures.

Ideally we should assure that no data lives the setup after the procedure - but just lighting everything on fire will never feel good enough to be implemented, so I'm out of ideas here.

This protocol still has a grave flaw, the electors can prove how they voted. Impossibility of proof is at odds with verification, but I still think there must be a way to make the proof physically hard.

Re: Fraud possible in Brazil's e-voting system

#49
post #7
post #5

SOAP BOX = 1 For what it's worth, e-voting isn't verifiable directly, unless it's done in a way linked to voter identities. Even then, it's highly exploitable, but it is verifiable, depending on the implementation. A trustworthy election embodies these four ideas to the maximum extent possible: 1. Anonymity. Votes cast are not linked to voters who cast them. 2. Transparency. The record of the voter intent, election l…

> For what it's worth, e-voting isn't verifiable directly, > unless it's done in a way linked to voter identities You're missing out on the last 20 years of crypto research. I'd say we're not there yet, but people have been thinking hard about things such as verifiability (with vote confidentiality of course!), coercion resistance etc, and have come up with really cool ideas. As with his other work, David Chaum has s…

Get back to me when there is a chain of trust between voter intent and the actual record of the vote.

Electronic systems do not actually record the voter intent, just an interpretation of it.

Note, the confidentiality is not the same as anonymity. This is a link to voter identities. It's just not made public, but it's there.

A nice, robust, human readable, court room compatible vote by mail works very well, and it embodies the four basic ideas I mentioned above. It can be manually done, or electronically counted and audited too. Whatever works.

Really, e-voting is a solution looking for a problem. Making fancy systems really isn't getting at the core issue; namely, turnout and suppression.

Not a one of those cool ideas will work out, unless it's linked to people like we do bank transactions. Even then, the voter will be in a forced position of trust as they must allow the technology to interpret their intent instead of recording their intent directly onto a trusted record.

Re: Fraud possible in Brazil's e-voting system

#50
post #7

Earlier quoted context omitted.

> For what it's worth, e-voting isn't verifiable directly, > unless it's done in a way linked to voter identities You're missing out on the last 20 years of crypto research. I'd say we're not there yet, but people have been thinking hard about things such as verifiability (with vote confidentiality of course!), coercion resistance etc, and have come up with really cool ideas. As with his other work, David Chaum has s…

Also check Microsoft research U-Prove ( http://research.microsoft.com/en-us/projects/u-prove/ ) or IBM Identity Mixer ( http://www.zurich.ibm.com/security/idemix/ ), both are Identity systems that allow casting electronic votes anonymously. I wonder if we will ever get to a point where that kind of crypto is explained enough that we collectively trust it as much as pen and paper.

There still exists a forced trust by the voter in that they must trust the machine to parse their voter intent and must trust it to use that intent to contribute to the overall tally.

A machine presents a user with some interface, and they make a selection and they get told something. They have no identifiable way to see the record of their intent is accurate, or even will be used.

With pen and paper, the intent of the voter is what we record and that record is used to arrive at the tally to determine the election.

With a machine, we do not record the voter intent, only what a machine determined that intent to be.

Actually recording the voter intent means being able to evaluate that intent in a court of law, vote by vote, if needed. Given the impact law and government has on us, it's not too much to ask we actually do record intent.

Post reply on HN